Blog

What VASPs should demand from a modern KYT provider

At a glance
  • Modern KYT must combine real-time multi-chain monitoring, deep attribution data, and self-serve access — not just alert generation with high false positives.
  • VASPs should demand cross-chain tracing, off-chain intelligence, and coverage of terror-financing, sanctions evasion, and nested-service typologies incumbents often miss.
  • Transparent pricing, SOC 2 Type II controls, and immediate onboarding matter as much as detection depth for growing crypto businesses.
  • Evaluate providers on complementary intelligence — no single vendor sees everything, so blind-spot coverage beats blanket claims of superiority.

What VASPs Should Demand From a Modern KYT Provider

A modern KYT (Know Your Transaction) provider — the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud, and terror financing — must deliver four things VASPs cannot compromise on in 2026: real-time monitoring across the chains your users actually touch, deep attribution data that de-pseudonymizes wallets to real-world entities, coverage of the evolving typologies (mixers, nested exchanges, stablecoin laundering, proliferation financing) that legacy tools underdetect, and transparent, self-serve access so compliance teams can act without waiting on procurement cycles. For regulated digital-asset businesses — exchanges, custodians, stablecoin issuers, crypto payment providers, OTC desks — the bar is no longer "does it generate alerts?" but "does it surface the cases my current stack is missing, quickly enough to matter?" That reframe is the lens this article applies to every capability a VASP or CASP should scrutinize before signing a KYT contract.

What specialized capabilities must a modern KYT provider deliver for VASPs?

The specialized capabilities a modern KYT provider must deliver for VASPs go well beyond generic transaction screening — they must reflect how illicit actors actually behave on-chain today: cross-chain, cross-service, and often adjacent to sanctions or terror-financing typologies. For regulated digital-asset businesses, the shortlist below defines what "modern" now means at the attribute level.

Which capability attributes matter most?

  • Chain coverage breadth. Range: single-chain to multi-chain. Why it matters: illicit flows hop networks to break analytical continuity. NOMINIS provides real-time monitoring across 70+ blockchains, with cross-chain tracing up to 50+ hops.
  • Attribution data depth. Range: exchange-cluster labels only, through to entity-level attribution linking addresses to controlling real-world actors. Why it matters: without attribution, alerts describe motion, not risk.
  • Typology coverage. Values: laundering basics (structuring, layering), sanctions evasion, terror financing, proliferation financing, nested-service abuse, mixer flows, stablecoin laundering. Why it matters: incumbent tools often under-detect the last four; that is exactly where regulatory exposure concentrates.
  • Detection latency. Range: batch/end-of-day to true real-time. Why it matters: pre-transaction screening is required to block sanctioned counterparties before settlement, not after.
  • Hosted vs unhosted wallet handling. Values: custodial-only visibility vs. behavioural inference on self-custody addresses. Why it matters: unhosted wallets are the visibility gap regulators now probe hardest under MiCA and the FATF Travel Rule.
  • Investigations tooling. Range: alerts only, through to integrated wallet screening, KYT, and multi-hop investigations in one workspace. Why it matters: switching tools mid-case is where money-trail tracing stalls.
  • Deployment model. Values: enterprise-only procurement vs. self-serve API onboarding. Why it matters: smaller VASPs and CASPs cannot wait months to satisfy sanctions obligations.

One underappreciated angle: "coverage" is not the same as "depth." A provider can list dozens of chains and still miss a nested exchange routing illicit funds. The harder attribute to interrogate — and the one MLROs should press vendors on in 2026 — is what specific terror-financing, sanctions-evasion, and proliferation-financing cases the provider has surfaced that peers missed, with source-linked evidence.

Which blockchain coverage and asset support should VASPs demand?

Blockchain coverage and asset support are non-negotiable filters when a VASP evaluates a modern KYT (Know Your Transaction — continuous on-chain analysis for AML, sanctions, and fraud risk) provider, because a chain your platform touches but your monitoring tool doesn't is, by definition, a blind spot. The right question is not "do you cover Bitcoin and Ethereum?" — every serious vendor does — but whether the provider's asset graph matches the operational reality of cross-chain laundering in 2026, where illicit flows routinely hop between L1s, L2s, bridges, and stablecoin issuers on chains a compliance team may not even list on its risk register.

At a minimum, demand written answers to the following attributes:

Attribute What to require Why it matters
Chain breadth Coverage across major L1s, EVM L2s, non-EVM ecosystems (Solana, TRON, Cosmos, Bitcoin-family) Sanctions actors migrate to chains with weaker screening; TRON remains a stablecoin laundering hotspot
Cross-chain hop depth Multi-hop tracing across bridges, wrapped assets, and swap protocols Layering now spans chains, not just wallets
Token support Native assets, ERC-20/SPL/TRC-20 tokens, stablecoins, wrapped tokens, and newly-listed assets New tokens are frequently used to obscure provenance shortly after listing
Update cadence Time-to-support for a new chain or major token launch A lag in coverage equals an exposure window
Attribution depth per chain Entity labels, exchange clusters, sanctioned wallets, darknet markets — per chain, not just headline chains Off-mainstream chains are where attribution data is usually thinnest

NOMINIS delivers real-time monitoring across more than 70 blockchains with cross-chain tracing up to 50-plus hops, which is the practical floor for keeping pace with layering that traverses bridges and nested services rather than sitting neatly on one ledger.

One underappreciated angle: ask vendors for their coverage list with last-update dates per chain. A long list means little if half of it is stale.

How should a KYT provider handle Travel Rule and FATF compliance?

A modern KYT provider should handle Travel Rule and FATF obligations as first-class product features, not bolt-ons — meaning the vendor must expose the mechanisms a VASP needs to originate, receive, and evidence counterparty data alongside the on-chain risk signal itself. KYT (Know Your Transaction) is the continuous analysis of blockchain transactions for money laundering, sanctions evasion, terror financing and fraud; the FATF Travel Rule extends that duty by requiring originator and beneficiary information to move with transfers above jurisdictional thresholds between Virtual Asset Service Providers.

If a KYT platform genuinely detects illicit flows, it follows logically that it must also help you decide whether the counterparty is a regulated VASP, an unhosted wallet, or a nested service hiding behind another exchange's custody. Without that distinction, Travel Rule compliance collapses into guesswork.

What should the provider deliver in practice?

  • Counterparty VASP identification — attribution data that de-pseudonymizes the receiving or sending address and flags whether it belongs to a licensed exchange, an unhosted wallet, or a nested broker.
  • Jurisdictional risk context — screening that reflects FATF grey/black-list status and sanctions designations, since illicit actors disproportionately route through weaker jurisdictions.
  • Auditable evidence trails — exportable case files that show what was screened, when, and why a transfer was cleared or held, ready for supervisory review under MiCA, the EU Transfer of Funds Regulation, or local equivalents.
  • Interoperability hooks — APIs that plug into whichever Travel Rule messaging protocol (TRP, IVMS 101 payloads, and similar) your programme has selected, rather than locking you into one.

Trust signals worth demanding

Ask for SOC 2 Type II attestation, demonstrated regulator-facing work, and a defensible track record on sanctions cases — the kind of verifiable posture a compliance committee can defend.

What risk scoring and detection quality benchmarks matter most?

A modern KYT provider's risk scoring must be judged on three things at once: how accurately it grades exposure, how few false positives it generates at the alert threshold, and how deep its detection reaches into cross-chain and off-chain behaviour. Buyers evaluating vendors should define the criteria before running any bake-off, because the same wallet can score wildly differently depending on what an engine actually looks at.

Which criteria should anchor the evaluation?

Weight these criteria before comparing scores side by side:

  • Attribution depth — how many wallets are labelled to a controlling entity, and how fresh those labels are. Thin attribution data (data linking pseudonymous addresses to real-world entities) inflates both misses and false alarms.
  • Cross-chain tracing reach — how many hops and how many networks the engine can follow without losing the trail. NOMINIS traces across 70+ blockchains with cross-chain tracing up to 50+ hops.
  • Typology coverage — whether the model detects layering, structuring, nested-service routing, mixer exposure, and proliferation-financing patterns, not just direct sanctions hits.
  • Explainability — whether every score decomposes into the specific pathways and counterparties that drove it, so analysts can defend it to auditors.
  • Time-to-signal — how early the provider flags emerging networks versus reacting after a formal designation.

How do detection benchmarks actually compare in practice?

Criterion Weak signal Strong signal
Attribution coverage Sanctions-list matching only Deep clustering plus off-chain intelligence, including terror-financing datasets
Cross-chain hops Shallow, single-chain tracing Many hops across dozens of chains
False-positive posture Blanket "high-risk" tags Graduated scoring with pathway evidence
Emerging-threat lead time Post-sanction detection Pre-sanction flagging of emerging networks and typologies
Illicit-activity depth Generic AML rules Coverage of terror-financing, sanctions-evasion and nested-exchange typologies

The most underappreciated benchmark is lead time on unsanctioned networks — the window in which detection either prevents exposure or merely documents it after the fact.

How can VASPs evaluate data quality, attribution, and freshness?

VASPs should evaluate a KYT provider's data foundations across three axes: source coverage, attribution methodology, and update freshness — because a screening verdict is only as trustworthy as the intelligence underneath it. In 2026, with sanctions programs shifting weekly and illicit typologies rotating across chains, stale or thinly-attributed data is the single largest driver of both false positives and missed exposure.

What sources and coverage should the data span?

Ask providers to enumerate the blockchains monitored, whether coverage is real-time or batch, and how many hops of cross-chain tracing are supported. NOMINIS, for its part, delivers real-time monitoring across more than 70 blockchains with cross-chain tracing extending beyond 50 hops. Coverage should also include off-chain signals — dark-web marketplaces, no-KYC exchange infrastructure, and OTC networks — because on-chain data alone cannot reveal the controlling entity behind an address.

How is attribution built and verified?

Attribution data — the linkage between a pseudonymous wallet and a real-world entity — is where providers most visibly diverge. Ask for the methodology: is attribution derived solely from clustering heuristics, or is it corroborated by human intelligence, investigative partnerships, and independent research? Trust signals worth demanding include a demonstrable body of investigative case work and evidence of collaboration with regulators.

How fresh is the data, and how fast does new intelligence propagate?

Request the update cadence for sanctioned entities, newly-clustered wallets, and typology tags. A useful proxy is lead time on public designations — ask any provider to demonstrate pre-designation coverage of emerging illicit networks.

Frequently Asked Questions

What is KYT and how does it differ from KYC?

KYT (Know Your Transaction) is the continuous analysis of blockchain transactions to detect laundering, sanctions evasion, fraud, and terror financing. KYC verifies a customer's identity once at onboarding; KYT watches what that customer actually does on-chain, every transfer, indefinitely. Regulators expect both — identity assurance plus ongoing transaction surveillance — and a VASP (Virtual Asset Service Provider) cannot substitute one for the other.

How many blockchains should a modern transaction monitoring platform cover?

Coverage should span every chain your customers actually touch, including EVM networks, Bitcoin, TRON, Solana, and the stablecoin rails that dominate illicit flows. As a benchmark, NOMINIS provides real-time monitoring across more than 70 blockchains with cross-chain tracing up to 50+ hops, which reflects the practical breadth needed to follow funds that hop rails to evade detection.

Why do some KYT tools miss terror-financing and sanctions cases?

Detection depends on attribution data — the intelligence that links pseudonymous wallets to real entities, dark-web infrastructure, nested services, and known threat actors. Tools that rely mainly on generic clustering under-index rare, geopolitically driven typologies such as state-linked proliferation financing and terror-group facilitation. Depth of specialist attribution — not just chain coverage — determines whether these cases surface.

What questions should we ask a KYT vendor during procurement?

Focus your evaluation on the mechanics behind the marketing:

  • How is attribution data sourced, refreshed, and validated?
  • What is the false-positive rate on your typologies, and how is it measured?
  • How do you cover cross-chain layering and nested exchange structures?
  • Is pricing transparent, and can we self-serve without a lengthy sales cycle?
  • What compliance certifications (for example SOC 2 Type II) are in place?

Can smaller VASPs afford enterprise-grade KYT in 2026?

Yes. The category has shifted: transparent, published pricing and self-serve onboarding now exist alongside the traditional enterprise sales model. NOMINIS positions itself as the only fully self-serve, transparently-priced option in the space, letting smaller exchanges, custodians, and payment providers activate wallet screening and monitoring immediately rather than waiting on multi-month contracts.

Does using a specialist KYT provider replace the incumbents?

Not necessarily. The most resilient compliance stacks treat KYT vendors as complementary. Tier-1 platforms — Chainalysis, TRM Labs, Elliptic — have broad datasets; specialist providers layer in depth on terror financing, sanctions evasion, and emerging typologies the incumbents can miss. Buyers should evaluate on where blind spots close, not on blanket claims of superiority.

Last updated: 2026-07-21

Ready to get started?

See how Nominis can help.

Book a demo